CPENT Sample Questions

CPENT Sample Questions & Answers

Web application testing against the OWASP Top 10 carries the most weight, framed by scoping, OSINT gathering, social-engineering attempts, network probes from outside, inside, and the perimeter, wireless, IoT, and OT testing, cloud assessment, and reporting.

Launch the full CPENT simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Open-Source Intelligence (OSINT) · OSINT Collection and Analysis

    A penetration tester wants to use Google Dorks to find publicly exposed PDF documents on a target website 'target-site.com' that might contain 'confidential' in the text. Which syntax is correct?

    Show answer & explanation

    Correct answer: C

    The correct Google Dork syntax uses site: to restrict results to the specific domain, filetype: to specify the file extension (pdf), and quotes around confidential to search for that specific string within the files.

  2. Question 2Intermediate

    Open-Source Intelligence (OSINT) · OSINT Collection and Analysis

    You are performing a DNS analysis and suspect that the target's nameserver is misconfigured to allow Zone Transfers. You are using the dig command on a Linux system. Which command syntax would you use to attempt a full zone transfer for the domain example.com from the nameserver ns1.example.com?

    Show answer & explanation

    Correct answer: A

    The AXFR query type is used to request a full zone transfer. The syntax dig @ -t AXFR directs the request specifically to the authoritative nameserver. If successful, this reveals all DNS records in the zone.

  3. Question 3Intermediate

    Open-Source Intelligence (OSINT) · OSINT Collection and Analysis

    A security consultant is using Shodan to identify industrial control systems exposed to the internet. They want to search for devices running the Modbus protocol on the standard port. Which search query should they use?

    Show answer & explanation

    Correct answer: B

    Modbus typically runs on TCP port 502. The Shodan search query port:502 filters for this port, and adding modbus helps refine the results to devices identifying with that protocol banner.

  4. Question 4Intermediate

    Social Engineering Penetration Testing · Social Engineering Techniques

    During a social engineering engagement, you plan to use the Social-Engineer Toolkit (SET) to harvest credentials. You want to clone the target's corporate login page and host it on your attacking machine, then email a link to the employees. Which attack vector in SET should you select?

    Show answer & explanation

    Correct answer: B

    This is the correct path in the SET menu. Website Attack Vectors allows web-based attacks; Credential Harvester focuses on collecting usernames/passwords; Site Cloner automatically copies the target URL's HTML to the attacker's server.

  5. Question 5Beginner

    Social Engineering Penetration Testing · Social Engineering Techniques

    A penetration tester is drafting a phishing email targeting C-level executives. The email is crafted to look like a subpoena from a federal court, urging immediate action. This specific type of social engineering attack is known as:

    Show answer & explanation

    Correct answer: C

    Whaling is a specific form of spear-phishing that targets high-profile individuals ('big fish') like CEOs, CFOs, or other C-level executives. The content is usually tailored to legal, executive, or financial matters.

  6. Question 6Intermediate

    Network Penetration Testing - External · External Network Assessment

    You are attempting to scan a target network that is protected by an Intrusion Detection System (IDS). You want to fragment your Nmap scan packets to make it harder for the IDS to recognize the scanning signature. Which Nmap switch should you use?

    Show answer & explanation

    Correct answer: B

    The -f switch in Nmap causes the requested scan (including ping scans) to use tiny fragmented IP packets. This splits the TCP header over several packets to make it harder for packet filters, intrusion detection systems, and other annoyances to detect what you are doing.

  7. Question 7Intermediate

    Network Penetration Testing - External · External Network Assessment

    While conducting an external penetration test, you discover a Windows server with Port 445 open. You want to check for the MS17-010 (EternalBlue) vulnerability using Nmap's scripting engine. Which command is MOST appropriate?

    Show answer & explanation

    Correct answer: B

    This command specifically targets port 445 and invokes the smb-vuln-ms17-010 script from the Nmap Scripting Engine (NSE) to check for the EternalBlue vulnerability.

  8. Question 8Advanced

    Network Penetration Testing - Internal · Internal Network Assessment

    You are performing a penetration test on a corporate network and have obtained a foothold on a machine in the DMZ. You want to scan the internal network (192.168.10.0/24) but cannot route traffic directly from your attack machine. You decide to use ProxyChains with an SSH tunnel. Which of the following describes the correct setup?

    Show answer & explanation

    Correct answer: C

    Dynamic Port Forwarding (-D) creates a SOCKS proxy on the local machine (attacker) that routes traffic through the SSH connection to the remote host (DMZ). ProxyChains is then configured to point to this local SOCKS proxy port (default 9050), allowing tools to run through the tunnel.

  9. Question 9Intermediate

    Network Penetration Testing - Internal · Internal Network Assessment

    During an internal assessment, you identify a Windows environment using LLMNR and NBT-NS. You decide to use Responder to capture hashes. After running Responder, you capture a NetNTLMv2 hash. Which tool and mode would you use to crack this hash?

    Show answer & explanation

    Correct answer: C

    In Hashcat, mode 5600 is used for NetNTLMv2 hashes. Responder typically captures these when poisoning LLMNR/NBT-NS requests.

  10. Question 10Intermediate

    Network Penetration Testing - Internal · Internal Network Assessment

    You have compromised a domain user account and are now mapping the Active Directory trust relationships. You want to identify if there is a path to the Domain Admin group using a graphical interface. Which tool is BEST suited for this purpose?

    Show answer & explanation

    Correct answer: C

    BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. It visually maps attack paths (like ACLs, group memberships, sessions) that can lead to Domain Admin privileges.

Ready for the real thing?

The full CPENT simulator has every exam-style question, timed mode, and instant scoring.

Go to the CPENT simulator →